Malicious code in stellarfixer (npm)
The npm package stellarfixer contains malicious code that executes a .NET remote-access trojan on Windows hosts during installation. The trojan establishes command-and-control communication, captures credentials via keystroke logging, records webcam frames, and propagates to removable drives.
- Disclosed
- Last updated
- Blast radius
- Windows hosts installing the package; potential for worm-like USB propagation to connected removable drives
- Ecosystems
- Attack vectors
- Affected entities
- stellarfixernpm package containing malicious postinstall script
The npm package stellarfixer was found to contain malicious code distributed via a postinstall script that unconditionally executes a bundled Windows PE binary (bin/stellarfn.exe) on package installation.\n\nThe binary is a .NET remote-access trojan with extensive malicious capabilities: it establishes a socket-based command-and-control channel with plugin loading support, installs a system-wide keyboard hook to capture credentials from all active windows, captures webcam frames, and includes mechanisms to propagate to removable USB drives. The trojan also implements anti-analysis and anti-removal features including antivirus exclusions and process-critical flags.\n\nInstallation of this package on a Windows host results in immediate full system compromise, remote attacker control, credential theft, and potential worm-like propagation via USB media. The incident was identified and credited to the OpenSSF malicious packages project.
Indicators of compromise
- Packages
- stellarfixer
Remediation
- Immediately uninstall the stellarfixer package from all systems
- Scan Windows hosts that installed this package with updated antivirus/anti-malware tools
- Reset credentials for any accounts used on affected systems
- Inspect removable USB drives connected to affected systems for malware propagation
- Review network logs for suspicious outbound connections from affected hosts
- Consider this a full system compromise; reimaging affected Windows hosts is recommended for critical systems
Sources
- GitHub Advisory GHSA-hgvp-g7pr-267g · GitHub Advisory Database
Cite this entry
"Malicious code in stellarfixer (npm)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed August 5, 2026; last updated August 5, 2026. https://supplychainattack.org/incident/malicious-code-in-stellarfixer-npm-1ozoc3
Suggest a correction
Found an error or have a newer source? Corrections to factual errors take priority over new entries.
Related incidents
- containedcritical
Malicious code in checkout-desktop-total (npm)
The npm package checkout-desktop-total contained malicious code that executes a hidden loader on import, downloading and running platform-specific native payloads from attacker-controlled Cloudflare Workers hosts or reconstructing them via DNS TXT records under wel1.ru. Any system that imported this package should be considered compromised.
npmCompromised package - resolvedcritical
Malicious code in epic-common-node (npm)
The npm package epic-common-node was found to contain malicious code. The package has been identified and reported through GitHub Security Advisory GHSA-m36g-mhjr-ww2c.
npmCompromised package - containedcritical
Malicious code in epic-common (npm)
The npm package epic-common was found to contain malicious code. The package was identified by Amazon Inspector and reported through the OpenSSF malicious packages database.
npmCompromised package - containedcritical
Malicious code in pfp-forms-sme-loan (npm)
The npm package pfp-forms-sme-loan contains malicious code that executes a hidden loader on import, downloading and running platform-specific native payloads from attacker-controlled Cloudflare Workers hosts or reconstructing them via DNS TXT records under well1.site. Any system that imported this package should be considered compromised.
npmCompromised packageMalicious commit